为提高Tor匿名通信系统的安全性,通过分析Tor系统中目录服务器可能采取的攻击方法,提出一种基于目录服务器保护的改进方案。通过在用户与目录服务器之间加入一个P2P构架网络,并在网络中设置随机抛弃参数动态调整安全参数,增加攻击者对目录服务器攻击的代价,从而提高了Tor系统的安全性。从攻击代价的角度对Tor系统安全性进行了理论分析,结果表明,Tor系统安全性的提升程度取决于嵌入P2P网络的规模和随机抛弃参数,该方案可有效改进Tor系统的安全性。
To enhance the security of the Tor anonymous communication system, by analyzing possi-ble attacks on the directory server, an improved defense scheme is proposed. A P2P network be- tween the users and the directory server is added, with dynamic security parameters configured, and the costs of launching an attack are increased. Theoretical analysis shows this security enhancement depends on the scale of the P2P network and those dynamic parameters.